First published: Tue Aug 29 2023(Updated: )
An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Frrouting Frrouting | <=9.0 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
Fedoraproject Fedora | =39 | |
redhat/frr | <9.1 | 9.1 |
redhat/frr | <8.5 | 8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-41359 is critical with a severity value of 9.1.
CVE-2023-41359 affects FRRouting versions up to and including 9.0.
CVE-2023-41359 is an out-of-bounds read vulnerability in bgp_attr_aigp_valid function in bgpd/bgp_attr.c of FRRouting.
CVE-2023-41359 can be exploited by causing an out-of-bounds read in bgp_attr_aigp_valid function during AIGP validation.
Please refer to the official reference for the fix of CVE-2023-41359.